๐บ๐ธ
TPI-Abuse
2026-09-21 06:21:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:21:18.325909 2026] [security2:error] [pid 3879768:tid 3879768] [client 34.80.137.17:38294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "automatebi.whitmarshinc.com"] [uri "/@fs/app/.env"] [unique_id "arDM3jrIEMhy4p2Z3MEw8gAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:57:08
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:57:04.432442 2026] [security2:error] [pid 21414:tid 21414] [client 34.80.137.17:43926] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.thenowhere-men.com|F|2"] [data ".thenowhere-men.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.thenowhere-men.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.thenowhere-men.com"] [unique_id "arDHMCX1fZfcJpcZe2NKRAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:30:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:30:37.027452 2026] [security2:error] [pid 16631:tid 16631] [client 34.80.137.17:51164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thehiddengemmalta.com"] [uri "/scripts/.env"] [unique_id "arCy7dOHgd0c46ynSyg4MAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-21 04:06:48
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:05:07
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:04:56.982393 2026] [security2:error] [pid 23323:tid 23323] [client 34.80.137.17:51862] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tausiet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tausiet.com"] [uri "/z9x8c7v6b5-debug-trigger-tausiet.com"] [unique_id "arCs6FctKe7FmB5RLMeVQQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:27:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:27:44.605125 2026] [security2:error] [pid 8572:tid 8572] [client 34.80.137.17:41076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.writebetweenthelines.com"] [uri "/.env.prod"] [unique_id "arCkMBkOE5CU4FCCRy8cZwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:02:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:01:56.643283 2026] [security2:error] [pid 32140:tid 32140] [client 34.80.137.17:60874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.webserviceswest.com"] [uri "/userfiles"] [unique_id "arCQFN-OK-9lmwgpweLISAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:08:55
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:08:51.029600 2026] [security2:error] [pid 25402:tid 25402] [client 34.80.137.17:54908] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.zodiacwin.com|F|2"] [data ".zodiacwin.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.zodiacwin.com"] [uri "/z9x8c7v6b5-debug-trigger-www.zodiacwin.com"] [unique_id "arCDo_U_-VUmbkRmM8hGUAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:50:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:49:59.584662 2026] [security2:error] [pid 5905:tid 5905] [client 34.80.137.17:46218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.voltbox.com"] [uri "/.env.old"] [unique_id "arB_N1A1ci7s15gYEnvqmQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:21:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:21:03.815274 2026] [security2:error] [pid 29300:tid 29300] [client 34.80.137.17:59820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tedharris.com"] [uri "/.env.production"] [unique_id "arB4b-7hSVRIR5xmSqo-lQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:36:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:36:47.726301 2026] [security2:error] [pid 7779:tid 7779] [client 34.80.137.17:56806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.thebestac.com"] [uri "/.env.local"] [unique_id "arBuDx3wc9jz9t72su_HEQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:50:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:50:46.659422 2026] [security2:error] [pid 566:tid 566] [client 34.80.137.17:59816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.unfinishedepic.com"] [uri "/.git/HEAD"] [unique_id "arBjRvKyyVgEu7eh5iSAAQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:31:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:31:41.262920 2026] [security2:error] [pid 13967:tid 13967] [client 34.80.137.17:47270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.title40.com"] [uri "/.env"] [unique_id "arBezezvWLgHhoeGVXjRoQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:16:31
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:16:26.874112 2026] [security2:error] [pid 27873:tid 27873] [client 34.80.137.17:45890] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||teenybikini.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teenybikini.com"] [uri "/z9x8c7v6b5-debug-trigger-teenybikini.com"] [unique_id "arBbOs1X-O9aU-pqI4I00QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:56:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.137.17 (17.137.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:56:48.849621 2026] [security2:error] [pid 4487:tid 4487] [client 34.80.137.17:37022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vicrp.com"] [uri "/admin/.env"] [unique_id "arBWoLBllqnKydcP0WOQ7QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack